Card Testing Fraud Guide: What It Is, How It Works & How to Prevent It in 2026?

September 24, 2026

Key Takeaways (TL;DR)

  • Card testing fraud is when someone runs small, low-value transactions through a checkout to verify which stolen card numbers are still active, before using or selling the working ones.
  • Credit card testing fraud usually shows up as a burst of tiny charges or declines within seconds of each other, often from the same IP address or device.
  • Fraudsters run card testing two ways: manually testing a handful of cards by hand, or using automated bots to enumerate thousands of card and CVV combinations at once.
  • Global card fraud losses are projected to reach 41.06 billion dollars by 2030, and eCommerce fraud alone is expected to climb from 44.3 billion dollars in 2024 to 107 billion dollars by 2029.
  • Card testing fraud rarely stays contained. A verified card usually resurfaces weeks or months later at a completely different merchant, once the fraudster is ready to make a larger purchase.
  • Effective card testing fraud prevention combines AVS and CVV checks, transaction velocity limits, and behavioral or device intelligence rather than any single control on its own.
  • Balancing prevention with checkout experience matters just as much as blocking fraud, since overly strict rules turn away legitimate customers and cost you real revenue.

Table of Contents

  1. Card Testing Fraud: at a Glance
  2. What Is Card Testing Fraud?
  3. How Does Card Testing Fraud Work?
  4. The Scale of Card Testing Fraud in 2026
  5. Common Types of Card Testing Attacks
  6. Warning Signs: How to Spot Credit Card Testing Fraud?
  7. How Card Testing Fraud Impacts Your Business?
  8. Industries Most Targeted by Card Testing Fraud
  9. Card Testing Fraud Prevention: Core Techniques
  10. How to Respond to a Card Testing Attack
  11. How to Choose the Best Card Testing Fraud Prevention Tool?
  12. Card Testing Fraud vs. Other Payment Fraud Types
  13. Everything You Need to Know About Card Testing Fraud
  14. Stop Card Testing Fraud with Fraudio
  15. FAQs About Card Testing Fraud

Card Testing Fraud: at a Glance

AspectWhat You Need to Know
Definition
✦Fraudsters run small transactions with stolen card details to confirm which cards are still active.
Why it happens
✦A verified card is worth more, whether the fraudster uses it directly or sells it on the black market.
Typical amount
✦Often under a dollar, sometimes a few cents, to stay under the radar.
Attack methods
✦Manual testing by hand, or automated bot enumeration across thousands of cards at once.
Common targets
✦Checkout pages, donation forms, and subscription signups with light verification.
Warning signs
✦Rapid small transactions, high decline rates, and repeat attempts from one IP or device.
Business impact
✦Chargebacks, processing fees, infrastructure strain, and processor scrutiny.
Prevention tools
✦AVS, CVV checks, velocity limits, CAPTCHAs, and behavioral or device intelligence.
Scale of the problem
✦Global card fraud losses are projected to hit $41.06 billion by 2030.

What Is Card Testing Fraud?

Card testing fraud is when someone uses stolen card numbers, expiry dates, and CVVs to run small transactions through a checkout, purely to confirm which cards are still valid. It relies on the same legitimate payment rails every honest customer uses, which is part of what makes it hard to catch early.

If you're asking what card testing fraud is in plain terms, think of it as a filter. Fraudsters rarely acquire clean, verified card lists. Instead, they buy or trade raw batches of stolen numbers, often mixed with cards that have already expired or been reported stolen. Running each number through a live checkout sorts the working cards from the dead ones.

Fraudsters usually source this stolen data from data breaches, phishing campaigns, or dark web marketplaces. A payment platform with light verification, like a donation page or a low-cost subscription signup, gives them exactly what they need to run that sorting process undetected.

Once a card passes the test, its value jumps. The fraudster can use it directly for a larger purchase, or sell the verified details on criminal forums for a premium. Card testing fraud is rarely the final goal; it is the reconnaissance step that makes every later fraud attempt more efficient.

How Does Card Testing Fraud Work?

‍

A typical card testing fraud attack moves through a short, repeatable sequence:

Step 1: Acquire stolen card data

Fraudsters buy or trade lists of stolen card numbers, sourced from breaches, skimming devices, or phishing pages, often in batches of hundreds or thousands. 

These lists are commonly traded on dark web forums, where sellers bundle card numbers with partial cardholder details to make them more attractive to buyers.

Step 2: Run small test transactions

The fraudster, or a script acting on their behalf, submits low-value charges, frequently under a dollar, against a merchant's checkout. 

Digital goods, donation pages, and subscription trials are common targets because they process high volumes of small transactions already, which helps the test blend in with legitimate traffic instead of standing out.

Step 3: Read the response codes

An approved transaction confirms the card is active. Even a decline can leak information; a decline for insufficient funds tells the fraudster the card is real, while a decline for an invalid card number tells them to move on. 

Sophisticated fraudsters track these codes closely, since they reveal almost as much as an approval does.

Step 4: Sort the results

Cards that pass get flagged as verified. Cards that fail get discarded. 

This sorting step is what makes credit card testing fraud so efficient at scale, since a single script can clear thousands of numbers in minutes and hand the fraudster a clean, working list to act on.

Step 5: Use or sell the verified cards

The fraudster either makes a larger purchase directly or sells the verified card list, which fetches a higher price than an unverified one since the buyer knows it works. 

Verified lists routinely change hands multiple times before the card is ever used for a large purchase. This is also why card testing fraud is so hard to trace back to its source. 

The actual damage, a large fraudulent purchase or a wave of chargebacks, often shows up weeks or months later at a completely different merchant than the one where the testing happened.

The Scale of Card Testing Fraud in 2026

‍

Credit card testing fraud is not a fringe problem. In the first three quarters of 2025 alone, more than 500,000 cases of credit card fraud were reported to the Federal Trade Commission, nearly 180,000 more than the same period the year before. Card testing sits behind a meaningful share of that volume, since it's the entry point for so much of the fraud that follows.

The financial scale keeps climbing too. Global card fraud losses are projected to reach 41.06 billion dollars by 2030, and eCommerce fraud is expected to grow from 44.3 billion dollars in 2024 to 107 billion dollars by 2029, a 141% increase. Another research found that nearly 90 percent of businesses lost up to 9 percent of revenue to fraud in a single year.

None of this happens because merchants are careless. Card testing fraud looks like ordinary low-value traffic, and automated tools let a single fraud ring run thousands of test transactions across dozens of merchants in the time it takes an analyst to review one flagged case. 

That mismatch in speed is exactly why credit card testing fraud keeps growing even as awareness of it does too.

Common Types of Card Testing Attacks

Not every card testing fraud attempt looks the same, and the method usually determines how fast it moves and how visible it is.

Here are some common types of card testing attacks people usually face: 

1. Manual card testing

A fraudster tries a small number of cards by hand, adjusting details based on the decline codes they get back.

It is slow and low-volume, but it still produces a signal, usually a handful of small charges or declines from the same customer profile within a short window. 

Manual testing is more common with smaller-scale operators who bought or stole a limited number of cards and want to avoid the visibility that a large automated run would create.

2. Automated enumeration attacks

Bots submit card and CVV combinations at high speed, sometimes thousands of attempts in a few minutes.

This is the more damaging version of card testing fraud, since a single automated run can validate an entire stolen card list before a merchant's team even notices the spike. 

Enumeration attacks often rotate through proxy networks and residential IP addresses specifically to avoid triggering simple IP-based rate limits, which is why device and behavioral signals matter more than IP address alone.

3. BIN attacks

Instead of testing individual stolen cards, fraudsters use the bank identification number (the first six to eight digits of a card) and generate the remaining digits, expiry dates, and CVVs algorithmically.

A successful BIN attack can produce dozens of working card numbers from a single starting sequence, without the fraudster ever having stolen a real card in the first place. 

This makes BIN attacks especially concerning, since they do not depend on a prior data breach at all.

4. Card cracking

Card cracking targets gift cards, prepaid cards, and store credit accounts rather than traditional credit or debit cards.

Fraudsters use similar enumeration techniques to guess valid card numbers and PINs, then drain any available balance before the legitimate owner notices. 

Because gift card and prepaid systems often have lighter fraud controls than standard card networks, they tend to be an easier entry point for testing scripts to succeed on their first few attempts.

Warning Signs: How to Spot Credit Card Testing Fraud?

‍

Recognizing credit card testing fraud early keeps a small problem from turning into a large one. Now that you know what card testing fraud is and why it happens, the challenge becomes knowing which patterns to watch for. 

These are the signals worth watching for:

  • Rapid small transactions: A burst of low-value charges, often under a dollar, arriving in quick succession is one of the clearest signs of a card testing attempt in progress.
  • Multiple cards from one source: Several different card numbers attempted from the same IP address, device, or browser fingerprint points to someone cycling through a stolen list rather than a genuine customer.
  • High decline rates: A spike in declined transactions, particularly for reasons like invalid expiry date or incorrect CVV, suggests a fraudster is guessing at missing details.
  • Mismatched billing information: Transactions where the billing address, name, or ZIP code do not match the card's real details often indicate the person submitting the charge does not actually hold the card.
  • Unusual timing patterns: Test transactions often cluster at odd hours or arrive in evenly spaced intervals, which is a pattern human shoppers rarely produce.
  • New merchant accounts with heavy declines: Fraudsters sometimes specifically target newly onboarded merchants that have not yet built up a fraud history, since these accounts tend to have looser default settings.

How Card Testing Fraud Impacts Your Business?

‍

Now that we've covered what is card testing fraud and how it operates, it's worth spelling out exactly what it costs a business that gets targeted. Card testing fraud creates damage that goes well beyond the value of the test transactions themselves.

  • Financial losses come from chargeback fees, lost goods or services, and the processing costs tied to each fraudulent attempt, even the ones for a few cents. Small charges add up fast when a script is running thousands of them, and payment processors often charge a flat fee per transaction regardless of the amount, so a wave of one-cent test charges can still generate a meaningful bill by the time it's caught.
  • Operational overhead rises as your team spends time investigating spikes, tuning fraud rules, and responding to customer disputes. A single card testing wave can generate a disproportionate amount of manual review work relative to the dollar amount involved, since analysts still need to trace every flagged transaction back to a source before deciding how to respond.
  • Reputational damage follows when legitimate customers get caught in overly strict fraud rules put up in response to an attack, or when a data breach tied to card testing becomes public. Trust is expensive to rebuild once it slips, and customers who experience a false decline during checkout often simply complete their purchase somewhere else instead of trying again.
  • Processor and issuer scrutiny increases too. A merchant account with a high volume of declines or chargebacks tied to card testing fraud can face higher processing fees, additional compliance requirements, or in serious cases, the loss of its ability to process card payments at all. 

For a growing business, that kind of restriction can be far more damaging long-term than the fraud losses that triggered it in the first place.

Industries Most Targeted by Card Testing Fraud

Card testing fraud concentrates wherever checkout friction is low and transaction values are small. 

Understanding which industries attract the most attempts helps a fraud team prioritize where to tighten controls first: 

  • Digital goods and subscription platforms: Low-cost trials and microtransactions make it easy for a test charge to blend in with normal traffic.
  • Nonprofit and donation platforms: Donation forms often accept small amounts by design and apply lighter verification than a typical retail checkout.
  • eCommerce and retail: High transaction volume gives fraudsters cover, particularly on stores that do not enforce AVS or CVV checks consistently.
  • Gaming and in-app purchase platforms: Small microtransactions for virtual goods are a favorite target, since users routinely make dozens of tiny purchases already.
  • Travel and ticketing sites: Add-on purchases, like seat upgrades or insurance, are often priced low enough to serve as convenient test transactions.
  • Newly launched startups and early-stage platforms: Fraud teams at younger companies are often smaller, and default fraud settings are frequently looser during the first months after launch, which makes new checkout flows an appealing target before defenses mature.

If your platform falls into any of these categories, it is worth assuming you are already a target rather than waiting for a visible spike in chargebacks to confirm it. 

Card testing fraud tends to find the checkout flow with the least resistance, and it moves on the moment that flow gets harder to exploit.

Card Testing Fraud Prevention: Core Techniques

Card testing fraud prevention works best as a layered system rather than a single control. Here is what an effective setup typically includes.

  • Address Verification Service (AVS): Compares the billing address entered at checkout against the address on file with the card issuer, flagging mismatches that often indicate a stolen card.
  • CVV verification: Requiring the security code on every transaction confirms the person checking out has physical access to the card, which blocks a large share of automated enumeration attempts.
  • Velocity and transaction limits: Capping the number of attempts or the total dollar amount allowed per card, IP address, or device within a set window stops a script from clearing thousands of numbers in one pass. This is one of the highest-impact controls to implement first, since it directly targets the volume that makes automated card testing fraud profitable in the first place.
  • CAPTCHA and bot detection: Adding a challenge at checkout, especially after repeated failed attempts, filters out the automated scripts that power large-scale card testing fraud without adding friction for genuine one-time shoppers. The key is triggering it based on risk signals rather than showing it to every visitor, which keeps the checkout experience smooth for legitimate customers.
  • Device and behavioral intelligence: Profiling how a session interacts with a checkout page, including typing patterns, device fingerprint, and browsing behavior, helps separate real customers from scripts even on a fraudster's first attempt, before a single transaction has cleared or failed.
  • Machine learning transaction scoring: Models trained on transaction patterns adapt to new card testing fraud tactics as they emerge, catching attacks that static rules were never written to expect.
  • Geographic and category blocking: Restricting transactions from countries or merchant categories your business does not normally serve removes an easy path fraudsters otherwise rely on.

Pairing rules with a proper fraud detection setup that scores every transaction in real time, rather than relying on manual review after the fact, is what actually catches card testing fraud before it turns into a chargeback wave.

How to Respond to a Card Testing Attack?

Understanding what card testing fraud is only useful if it changes how fast you act once you spot it. If you suspect an active card testing fraud attempt, speed matters more than perfection. 

The goal is to contain the attack quickly without locking out legitimate customers who happen to share a payment pattern with the fraud.

Here’s a stepwise approach to help you respond effectively to a card testing attack: 

  1. Freeze the suspicious activity: Pause or block the transactions in question immediately to stop further attempts from the same source, whether that's a specific card range, IP address, or device fingerprint.
  2. Tighten verification temporarily: Apply extra checks, like CAPTCHA or manual review, to transactions matching the attack's pattern while you investigate, rather than applying it site-wide and frustrating every customer.
  3. Analyze the scope: Review transaction logs to identify how many cards were tested, which IPs or devices were involved, and whether any transactions actually succeeded and need separate follow-up.
  4. Notify your payment processor: Your processor or acquiring bank needs to know about the incident so they can monitor for related activity and support your response, since the same attack often hits several of their merchants at once.
  5. Report large-scale incidents: If the attack is significant, report it to law enforcement and your card network, since the same stolen card batch is often tested against multiple merchants and the pattern may already be on their radar.
  6. Review and adjust your defenses: Use what you learned to tighten velocity limits, add missing checks, or retrain fraud models before the next wave arrives, since card testing fraud rarely stops after a single attempt.

How to Choose the Best Card Testing Fraud Prevention Tool?

Building your own card testing fraud prevention stack from individual point solutions works for a while, but most fraud teams eventually outgrow that approach as attack volume grows and false positives start eating into legitimate revenue. 

If you are evaluating vendors instead, a few criteria separate genuinely effective tools from ones that just look good in a sales deck: 

1. Network-level data versus siloed models

Many fraud tools train only on each customer's own transaction history, which means new merchants start with almost no protection while the model builds up experience.

A provider that pools data across a broader network of customers catches known bad actors and BIN patterns from day one, not after months of ramp-up. 

This matters most for newer platforms that don't yet have years of their own transaction history to train a model on.

2. Real-time scoring, not just batch review

Card testing fraud plays out in seconds, not hours. A tool that only reviews transactions in nightly batches will always be a step behind an automated attack that clears thousands of cards in minutes.

Event-driven scoring that acts at the point of authorization is what actually stops a script mid-run, rather than just documenting the damage afterward.

3. Integration speed

Enterprise fraud platforms have historically taken 5 to 14 months to integrate, which is a long window to stay exposed.

Faster onboarding, measured in days or weeks rather than months, means protection starts working immediately instead of after a lengthy rollout. 

For a business already under active attack, that difference alone can determine how much fraud gets through before the tool is even live.

4. False positive management

A detection model that is too aggressive blocks legitimate low-value purchases and damages the checkout experience just as much as missed fraud damages your bottom line.

Ask vendors for real false decline numbers, not general claims, and find out how they tune sensitivity for your specific transaction mix rather than applying a one-size-fits-all threshold.

5. Pricing transparency

Card testing fraud prevention budgets are hard to plan around unpredictable fees.

Favor usage-based pricing with no setup costs over vendors that bury charges in multi-year contracts, since a transparent model also makes it easier to justify the investment to finance or leadership.

6. Proven results

Ask for case studies with concrete numbers, such as fraud caught earlier than legacy tools or measurable efficiency gains for the fraud team, rather than a features list with no evidence behind it. 

A vendor that can point to a specific, measurable outcome for a comparable customer is demonstrating something a generic feature comparison never can.

This is also where pairing card testing fraud prevention with a broader anti-money laundering platform matters, since verified stolen cards frequently feed into larger laundering operations further down the chain. 

Catching the testing stage early cuts that pipeline off before it reaches that point.

Card Testing Fraud vs. Other Payment Fraud Types

Card testing fraud gets confused with a few related terms, and the distinctions matter for how you respond. 

Here are some key comparisons you must know about: 

  • Card testing fraud vs. account takeover: Card testing fraud involves testing a fresh batch of stolen card numbers against a checkout, while account takeover involves a fraudster gaining control of an existing customer account. The two can overlap, but they call for different detection signals and different response steps.
  • Card testing fraud vs. friendly fraud: Friendly fraud happens when a legitimate cardholder disputes a charge they actually made, whereas card testing always involves a card the person running the transaction does not own. Friendly fraud is a billing dispute problem; card testing is a stolen-data problem.
  • Card testing fraud vs. triangulation fraud: Credit card testing fraud is a distinct, earlier step from triangulation fraud or straightforward card-not-present fraud. Card testing confirms a card works; the fraud that follows, including triangulation schemes involving a fake storefront, is what actually monetizes it.

Treating card testing as a standalone signal, rather than folding it into general chargeback monitoring, is what lets a fraud team catch a stolen card batch before it gets used for anything bigger.

This distinction also matters for how a business measures its own risk. 

A merchant that only tracks confirmed chargebacks will consistently underestimate its exposure to card testing fraud, since most test transactions never generate a dispute at all; they simply confirm a card works and move on. 

Tracking decline patterns and transaction velocity separately from chargeback rates gives a far more accurate picture of how often your checkout is being probed.

Everything You Need to Know About Card Testing Fraud

TopicKey Point
What is card testing fraud?
✦Using stolen card details to run small transactions and confirm which cards are still active.
Why do fraudsters do it?
✦A verified card is worth more, whether used directly or sold on the black market.
Attack methods
✦Manual testing, automated enumeration, and BIN attacks that generate card numbers algorithmically.
Common targets
✦Digital goods, donations, subscriptions, gaming, and travel add-ons.
Warning signs
✦Rapid small transactions, high decline rates, and repeat attempts from one IP or device.
Business impact
✦Chargebacks, operational overhead, reputational damage, and processor scrutiny.
Core prevention tools
✦AVS, CVV checks, velocity limits, CAPTCHA, device intelligence, and machine learning scoring.
Response steps
✦Freeze, tighten checks, analyze scope, notify processor, report, and adjust defenses.
Buyer's priorities
✦Network-level data, real-time scoring, fast integration, transparent pricing, and proven results.
Scale of the problem
✦Global card fraud losses are projected to reach $41.06 billion by 2030.

Stop Card Testing Fraud with Fraudio

Now that you know what card testing fraud is – how it spreads, and what to look for, the next step is putting a system in place that catches it before it costs you.

Card testing fraud moves in seconds, which is exactly why siloed, batch-based tools keep missing it. Fraudio's AI-Powered Payment Fraud Detection scores every transaction in real time at the point of authorization, built on a centralized dataset that learns from billions of transactions across our network rather than just one customer's history. That means a BIN attack or bot-driven enumeration pattern seen at one merchant helps protect every other business on the platform from day one.

We deploy in 3-14 days, instead of the 5-14 months time-frame enterprise platforms typically take. The platform runs on transparent, pay-per-use pricing with no setup fees or long-term lock-in. This fits teams that cannot afford to wait months for protection while a card testing fraud campaign runs unnoticed against a new or growing checkout flow.

Book a call with our team to see how Fraudio performs against your own transaction data, with zero commitment required.

FAQs About Card Testing Fraud

What is card testing fraud?

Card testing fraud is when someone uses stolen card numbers to run small transactions through a checkout, purely to confirm which cards are still active before using or selling the verified ones. The charges are usually under a dollar, sometimes just a few cents, to avoid drawing attention. It often serves as the first step before a larger fraudulent purchase happens elsewhere. Businesses that process high volumes of small transactions, like subscriptions or donations, are frequent targets.

How does credit card testing fraud actually work?

Credit card testing fraud works by running stolen card details through a merchant's checkout and reading the response. An approved transaction confirms the card works, while even a decline can reveal useful information, since a decline for insufficient funds still confirms the card is real. Fraudsters do this manually in small batches or through automated bots that test thousands of cards in minutes. Once a card is verified, its value increases significantly on criminal marketplaces.

How can I tell if my business is being targeted by card testing fraud?

You can tell your business is being targeted by card testing fraud when you see a burst of small transactions, often under a dollar, arriving in quick succession from the same IP address or device. High decline rates, especially for invalid CVV or expiry date errors, are another strong signal. Mismatched billing details and unusual timing patterns, like evenly spaced attempts, round out the common warning signs. Newly launched checkout flows are especially common targets.

What does effective card testing fraud prevention look like?

Effective card testing fraud prevention combines several layers rather than relying on one control. AVS and CVV checks catch a large share of basic attempts, while velocity limits stop scripts from clearing thousands of cards in one pass. CAPTCHAs filter out automated bots, and behavioral or device intelligence flags suspicious sessions even before a transaction completes. Machine learning scoring ties these signals together and adapts as new attack patterns emerge.

What happens if a business ignores card testing fraud?

If a business ignores card testing fraud, the immediate cost is usually chargebacks and processing fees on the fraudulent transactions themselves. Over time, ignoring the pattern lets fraudsters verify larger stolen card batches against your checkout, increasing the odds of a bigger fraudulent purchase later. Processors and card networks can also flag the merchant account for elevated scrutiny, leading to higher fees or restricted processing. Left unresolved, repeated incidents can damage customer trust and revenue.

Can card testing fraud happen even with small transaction amounts?

Yes, card testing fraud specifically relies on small transaction amounts, often under a dollar, because low-value charges are less likely to trigger a cardholder's attention or a bank's fraud alerts. Fraudsters deliberately choose amounts small enough to stay under most default fraud thresholds. This is exactly why relying only on dollar-value triggers for fraud review misses most card testing activity. Volume and velocity, not transaction size, are the more reliable signals to monitor.

Is card testing fraud the same as a data breach?

Card testing fraud is not the same as a data breach, though the two are closely connected. A data breach is how fraudsters typically obtain the stolen card numbers in the first place, while card testing fraud is the separate step of verifying which of those stolen numbers still work. A business can experience a card testing attack without ever having breached itself, since the stolen cards usually came from an entirely different source.

Isn't card testing fraud too small in dollar value to worry about?

Not when you consider what it enables. Card testing fraud transactions are intentionally small, but they are the reconnaissance step for larger fraud that often lands at a different merchant weeks later. Ignoring small-value test charges also leaves the door open for automated bots to clear thousands of cards through your checkout, generating disproportionate chargeback and processing costs relative to the value of the test transactions themselves.

‍

Measure results yourself !

How about trying our solution  and experiencing the next generation for yourself?